India’s Star Health confirms data breach after cybercriminals post customers’ health data online

Date:

Share post:


Star Health and Allied Insurance, one of the largest health insurance firms in India, has confirmed it was the target of a “malicious cyberattack,” some two weeks after cybercriminals claimed to post customers’ health records and other sensitive data online.

The Chennai-headquartered insurance giant told TechCrunch in a statement Wednesday that the cyberattack resulted in “unauthorized and illegal access to certain data,” though it stated its operations remained unaffected and services continued.

“A thorough and rigorous forensic investigation, led by independent cybersecurity experts, is underway, and we are working closely with government and regulatory authorities at every stage of this investigation, including by duly reporting the incident to the insurance and cybersecurity regulatory authorities apart from filing a criminal complaint,” the company said in its statement.

When asked by TechCrunch, Star Health would not say if the data breach included customers’ data.

Last month, a hacker group created chatbots on Telegram that leaked the alleged personal data belonging to 31 million Star Health policyholders and over 5.8 million insurance claims. The data included full names, phone numbers, and home addresses, as well as medical reports and insurance claims of individuals. The hackers also shared copies of customer ID cards and individuals’ tax details.

Star Health told TechCrunch at the time that the company was “investigating” the alleged theft.

Shortly after the hackers’ Telegram bots came to light, Star Health filed a legal complaint with the Madras High Court against Telegram for hosting the chatbots. The insurer also named Cloudflare in its lawsuit for its role in hosting the hacker group’s websites on its service.

India’s CERT-In told TechCrunch earlier that it was “already in process of taking appropriate action with the concerned authority.”

Details of the breach, and how the hackers obtained potentially millions of customers’ data, remain unclear.

The hackers’ website, used to publicize the Telegram bots sharing the allegedly stolen person data, includes a video allegedly showing screenshots and conversations between Star Health CISO Amarjeet Khanuja and the hacker group. TechCrunch is not linking to the site as it contains personally identifiable information.

The role of the company’s CISO in the cyberattack, if at all, is not yet known.

“We also want to categorically mention that our CISO has been duly co-operating in the investigation, and we have not arrived at any finding of wrongdoing by him till date. We request that his privacy be respected as we know that the threat actor is trying to create panic,” the insurer said Wednesday.

TechCrunch asked specific questions, including whether the insurer can confirm who accessed the data, whether it was an insider or a malicious intruder, and if it knows and can confirm what has been accessed or taken already. The insurer would not say.

Star Health, which provides health, personal accident, and overseas and travel insurance, has a network of more than 14,000 hospitals and over 850 branch offices across India. Star Health says on its website that it has provided health insurance coverage to 170 million individuals.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Zepto raises another $350 million amid retail upheaval in India

Zepto has secured $350 million in new funding, its third round of financing in six months, as...

Battery unicorn Northvolt files for bankruptcy, upending Europe’s industrial plan

Beleaguered Swedish battery manufacturer Northvolt announced today that it was filing for bankruptcy in the U.S., striking...

Brave Search adds AI chat for follow-up questions after your initial query

Brave announced on Thursday that it’s introducing an AI chat mode for follow-up questions based on initial...

Cruise fesses up, Pony AI raises its IPO ambitions, and the TuSimple drama dials back up

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of...

WhatsApp rolls out voice message transcripts

WhatsApp announced on Thursday it’s rolling out voice message transcripts. The Meta-owned company says the new feature...

Threads adjusts its algorithm to show you more content from accounts you follow

After several complaints about its algorithm, Threads is finally making changes to surface more content from people...

Spotify tests a video feature for audiobooks as it ramps up video expansion

Spotify is enhancing the audiobook experience for premium users through three new experiments: video clips, author pages,...

Candela brings its P-12 electric ferry to Tahoe and adds another $14M to build more

Electric passenger boat startup Candela has topped off its most recent raise with another $14 million, the...